Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown

CVE-2020-29215

Disclosure Date: June 15, 2021 (last updated February 22, 2025)
A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.
Attacker Value
Unknown

CVE-2017-17992

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action.
0
Attacker Value
Unknown

CVE-2017-17991

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
0
Attacker Value
Unknown

CVE-2017-17994

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.
0
Attacker Value
Unknown

CVE-2017-17995

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
0
Attacker Value
Unknown

CVE-2017-17989

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
0
Attacker Value
Unknown

CVE-2017-17993

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.
0
Attacker Value
Unknown

CVE-2017-17990

Disclosure Date: December 30, 2017 (last updated November 26, 2024)
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
0
Attacker Value
Unknown

CVE-2025-1606

Last updated February 24, 2025
A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of the file /admin/backup/backups.php. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2025-1607

Last updated February 24, 2025
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Employee Management System 1.0. This issue affects some unknown processing of the file /admin/salary_slip.php. The manipulation of the argument id leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0